Azure B2C自定义策略密码重置异常求助:链接无效/无法隐藏
Azure B2C自定义策略密码重置问题解决方案
一、隐藏密码重置链接(解决setting.forgotPasswordLinkLocation配置无效问题)
如果尝试配置<Item Key="setting.forgotPasswordLinkLocation">None</Item>未生效,按以下步骤调整:
- 确认页面布局版本
找到登录页面对应的ContentDefinition(通常为api.signuporsignin),确保其DataUri使用支持该设置的统一布局版本(如urn:com:microsoft:aad:b2c:elements:contract:unifiedssp:2.1.0及以上),示例配置:<ContentDefinition Id="api.signuporsignin"> <LoadUri>~/tenant/templates/AzureBlue/unified.cshtml</LoadUri> <DataUri>urn:com:microsoft:aad:b2c:elements:contract:unifiedssp:2.1.0</DataUri> <!-- 其他配置 --> </ContentDefinition> - 正确配置隐藏参数
在上述ContentDefinition的Metadata节点中添加隐藏设置,避免被其他配置覆盖:<ContentDefinition Id="api.signuporsignin"> <!-- 其他配置 --> <Metadata> <Item Key="setting.forgotPasswordLinkLocation">None</Item> </Metadata> </ContentDefinition> - 备选方案:清空链接文本
若上述方法仍无效,可在对应语言资源文件中将密码重置链接文本设为空:<LocalizedResources Id="api.signuporsignin.zh-CN"> <LocalizedStrings> <LocalizedString ElementId="forgot_password_link" StringId="forgot_password_link"> </LocalizedString> </LocalizedStrings> </LocalizedResources>
二、修复自定义密码重置流程(解决子旅程无法触发问题)
若要让本地用户密码重置正常运行,需确保子旅程配置正确且链接指向自定义策略端点:
- 验证密码重置子旅程配置
确认子旅程(如Id="PasswordReset")包含完整编排步骤:验证邮箱、重置密码、返回令牌,示例核心结构:<UserJourney Id="PasswordReset"> <OrchestrationSteps> <!-- 步骤1:显示邮箱输入页 --> <OrchestrationStep Order="1" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="PasswordResetUsingEmailAddressExchange" TechnicalProfileReferenceId="LocalAccountDiscoveryUsingEmailAddress" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤2:验证邮箱验证码 --> <OrchestrationStep Order="2" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="VerifyEmail" TechnicalProfileReferenceId="VerifyEmail" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤3:重置密码 --> <OrchestrationStep Order="3" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="ResetPassword" TechnicalProfileReferenceId="LocalAccountWritePasswordUsingObjectId" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤4:返回令牌 --> <OrchestrationStep Order="4" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" /> </OrchestrationSteps> <ClientDefinition ReferenceId="DefaultWeb" /> </UserJourney> - 修改登录页面的密码重置链接
替换默认的passwordreset.microsoftonline.com链接,指向自定义密码重置策略端点,在语言资源文件中更新:<LocalizedResources Id="api.signuporsignin.zh-CN"> <LocalizedStrings> <LocalizedString ElementId="forgot_password_link" StringId="forgot_password_link"> <Override Language="zh-CN"> <a href="https://你的租户名.b2clogin.com/你的租户名.onmicrosoft.com/B2C_1A_PasswordReset/oauth2/v2.0/authorize?client_id=你的客户端ID&response_type=code&redirect_uri=你的回调地址&scope=openid&state=12345">忘记密码?</a> </Override> </LocalizedString> </LocalizedStrings> </LocalizedResources> - 确保子旅程被正确引用
在RelyingParty节点中,确认密码重置策略已关联对应的用户旅程:<RelyingParty> <DefaultUserJourney ReferenceId="PasswordReset" /> <!-- 其他配置:技术配置、令牌签发等 --> </RelyingParty> - 排查基础策略冲突
检查b2ciefsetupapp生成的基础策略,确认没有禁用自定义密码重置的配置,比如默认的LocalAccountSigninWithLogonEmail技术配置是否覆盖了密码重置触发逻辑,确保自定义子旅程优先级更高。
内容的提问来源于stack exchange,提问作者Calin956
相关产品推荐
相关产品推荐

